CVE-2016-5056 describes a weak Pre-Shared Key (PSK) vulnerability in OSRAM SYLVANIA Osram Lightify Pro devices prior to 2016-07-26, where the PSK is limited to only 8 hexadecimal digits. This flaw carries a CVSS v3.0 score of 7.5 (HIGH), indicating that an unauthenticated attacker could remotely exploit this weakness with low complexity to achieve high confidentiality impact. Despite its severity, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, with only one mention and one article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= -CPE matchmatch criteria | cpe:2.3:a:osram:lightify_pro:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.